We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous... Read more
We are seeking a Senior Manager, Cybersecurity Governance, Risk & Compliance (GRC) to lead the development and continuous improvement of a mature cybersecurity governance and risk management framework. This role will provide strategic direction, independent challenge and practical guidance to ensure security controls, policies and processes align with business objectives, regulatory obligations and recognised industry standards. The successful candidate will work closely with technology, risk, legal, audit and operational teams to strengthen cyber resilience across the organisation.
Key responsibilities include owning and maintaining cybersecurity policies, standards, procedures and control frameworks; overseeing enterprise cyber risk assessments, risk registers, remediation plans and risk acceptance processes; and coordinating compliance activities against applicable laws, regulations and frameworks such as ISO 27001, NIST, CIS Controls and relevant privacy requirements. You will lead the preparation for internal and external audits, assessments and regulatory reviews, track findings through to closure, and provide clear reporting on risk exposure, control effectiveness, compliance status and key performance indicators to senior leadership and governance committees. The role will also support third-party risk management, security exception management, control testing and the development of governance processes for emerging technologies and change initiatives.
To succeed, you will bring significant experience in cybersecurity governance, risk and compliance, including leadership responsibility within a complex or highly regulated environment. You should have strong knowledge of security frameworks, regulatory expectations, risk methodologies, audit practices and control design, alongside the ability to translate technical issues into concise business-focused advice. Relevant professional certifications such as CISSP, CISM, CRISC, CISA, ISO 27001 Lead Implementer or Lead Auditor are desirable. Excellent stakeholder management, communication, analytical and influencing skills are essential, as is the ability to prioritise competing demands, lead improvement programmes and operate confidently with senior executives. A proactive, pragmatic and collaborative approach will be highly valued.
Read lessLeatherhead, England, United KingdomPermanent
We are seeking a Cybersecurity Compliance Officer to support the development, implementation, and ongoing improvement of information security... Read more
We are seeking a Cybersecurity Compliance Officer to support the development, implementation, and ongoing improvement of information security and compliance programmes. This role will help ensure that cybersecurity practices align with applicable laws, regulations, industry standards, and internal policies. You will work closely with technology, risk, legal, privacy, and business teams to identify compliance requirements, assess control effectiveness, and promote a strong culture of security and accountability.
Key responsibilities include maintaining cybersecurity policies, standards, procedures, and control documentation; coordinating internal and external audits; tracking remediation activities; and preparing clear compliance reports for senior stakeholders. You will conduct risk and control assessments, monitor regulatory and industry developments, support third-party security reviews, and help manage evidence collection for security frameworks such as ISO 27001, SOC 2, NIST, or equivalent standards. The role will also involve assisting with security awareness initiatives, reviewing exceptions, investigating control deficiencies, and recommending practical corrective actions. You will contribute to incident response exercises and ensure that lessons learned are reflected in relevant policies and processes.
The successful candidate will have experience in cybersecurity governance, risk, and compliance, with a strong understanding of information security controls, audit processes, and regulatory requirements. Familiarity with recognised frameworks such as ISO 27001, NIST CSF, CIS Controls, PCI DSS, or relevant privacy legislation is desirable. Professional qualifications such as CISA, CISM, CISSP, CRISC, or equivalent experience would be advantageous. You should have excellent analytical, organisational, written, and verbal communication skills, with the ability to explain complex requirements to both technical and non-technical audiences. A proactive, detail-oriented approach and the ability to manage multiple priorities in a collaborative environment are essential.
Read lessPreston, England, United KingdomPermanent
We are seeking an experienced Business Analyst to support cyber controls and compliance activities on a contract basis.... Read more
We are seeking an experienced Business Analyst to support cyber controls and compliance activities on a contract basis. The successful candidate will work with cybersecurity, technology, risk, audit and business stakeholders to understand regulatory obligations, assess control effectiveness and help strengthen the organisation’s overall control environment. This role is suited to someone who can translate complex security and compliance requirements into practical, clearly documented processes and actionable improvements.
Key responsibilities will include gathering and analysing business and control requirements; documenting current and future-state processes; mapping controls to relevant policies, standards and regulatory frameworks; and identifying gaps, risks, dependencies and opportunities for improvement. You will support control testing and remediation tracking, maintain accurate evidence and compliance records, and prepare clear reports for governance forums and senior stakeholders. The role will also involve coordinating with control owners, assisting with audit and assurance requests, monitoring remediation activities, and helping ensure that agreed actions are delivered within required timeframes. You may contribute to the development of procedures, risk assessments, management information and continuous improvement initiatives across cyber security and technology environments.
Applicants should have proven experience as a Business Analyst, ideally within cybersecurity, information security, technology risk, governance or regulatory compliance. Strong knowledge of cyber controls, risk management principles, audit processes and control frameworks such as ISO 27001, NIST, COBIT or similar is highly desirable. You will need excellent analytical, documentation and stakeholder-management skills, with the ability to communicate effectively with both technical and non-technical audiences. Experience using GRC, workflow, risk or reporting tools, together with a structured approach to managing multiple priorities, will be advantageous. The contract requires someone who is organised, collaborative, detail-focused and confident working independently in a changing environment.
Read lessLondon, England, United KingdomContract
We are seeking a Data Protection and Compliance Officer to support the development, implementation and continuous improvement of... Read more
We are seeking a Data Protection and Compliance Officer to support the development, implementation and continuous improvement of effective data protection and compliance practices. The successful candidate will help ensure that personal information is handled lawfully, securely and transparently, while promoting a strong culture of accountability across the organisation. This role will involve working with colleagues at all levels, providing practical advice and helping teams understand and meet their regulatory responsibilities.
Key responsibilities will include monitoring compliance with applicable data protection legislation, maintaining policies, procedures and records of processing activities, and supporting data protection impact assessments. You will manage and respond to data subject requests, personal data breaches and compliance queries, escalating issues where appropriate. The role will also involve conducting audits and compliance reviews, maintaining risk registers, tracking remedial actions, and assisting with the delivery of staff training and awareness programmes. You will work closely with internal stakeholders and, where required, external advisers, suppliers and regulatory bodies.
Applicants should have experience in data protection, information governance, risk, audit or a related compliance function, together with a sound understanding of relevant privacy principles and regulatory requirements. A recognised qualification in data protection, compliance, law, information security or a similar discipline would be advantageous. You will need excellent written and verbal communication skills, strong attention to detail and the ability to interpret complex requirements and translate them into clear, practical guidance. The ideal candidate will be organised, discreet and confident handling sensitive information, with the judgement to prioritise competing demands and challenge constructively. Experience of working with data mapping, incident management, policy development or compliance monitoring would be beneficial.
Read lessBlackburn, Scotland, United KingdomPermanent
We are seeking a Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer to strengthen enterprise-wide security governance... Read more
We are seeking a Senior Cyber Security Governance, Risk & Compliance (GRC) Engineer to strengthen enterprise-wide security governance and support the continuous improvement of cyber risk management practices. This role will provide expert guidance across security frameworks, policies, controls and assurance activities, helping to ensure that technology, business processes and third-party services meet regulatory, contractual and organisational requirements.
Key responsibilities include developing, maintaining and reviewing information security policies, standards and procedures; conducting risk assessments and control reviews; supporting audit and compliance programmes; and tracking remediation activities through to completion. You will coordinate evidence gathering, prepare clear reports for senior stakeholders, and advise on risk acceptance, treatment plans and control effectiveness. The role will also contribute to security architecture and project reviews, supplier and third-party risk assessments, business continuity activities, incident response governance, and the implementation of improvements aligned with recognised frameworks such as ISO 27001, NIST, CIS Controls or similar.
The successful candidate will have substantial experience in cyber security governance, risk and compliance, with a strong understanding of security controls, regulatory obligations, audit principles and risk management methodologies. Relevant certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Implementer or Lead Auditor are desirable. You should be confident engaging with technical and non-technical audiences, able to challenge constructively, and skilled at translating complex security issues into practical business recommendations. Strong analytical, documentation and stakeholder-management skills are essential, along with the ability to prioritise competing demands and work independently in a changing environment. Experience with GRC platforms, cloud security risk, third-party assurance and security metrics would be advantageous.
Read lessHuntingdon, England, United KingdomPermanent
We are seeking an experienced Data Protection and Compliance Officer to support the effective management of privacy, information... Read more
We are seeking an experienced Data Protection and Compliance Officer to support the effective management of privacy, information governance and regulatory compliance across the organisation. This role will provide practical advice on data protection requirements, help embed a culture of responsible information handling, and ensure that policies and procedures remain aligned with applicable legislation and recognised best practice.
Key responsibilities will include monitoring compliance with data protection laws and internal standards; maintaining and reviewing privacy notices, policies, records of processing activities and data retention schedules; advising colleagues on lawful processing, data sharing, consent, direct marketing and individual rights; and coordinating responses to access requests and other data subject enquiries. You will support privacy impact assessments, third-party due diligence, audits and compliance reviews, while helping to investigate and manage personal data breaches. The role will also involve delivering awareness training, preparing management information, tracking remedial actions and working with stakeholders to resolve risks in a timely and proportionate manner.
Applicants should have demonstrable experience in data protection, information governance, risk, audit or a closely related compliance role, together with a sound understanding of relevant privacy legislation and regulatory guidance. A recognised data protection or compliance qualification is desirable. You will be confident interpreting complex requirements, communicating clearly with both technical and non-technical audiences, and exercising sound judgement when handling sensitive information. Strong organisational skills, attention to detail and the ability to manage competing priorities are essential. The successful candidate will be proactive, discreet and collaborative, with the confidence to challenge constructively and promote continuous improvement in privacy and compliance practices.
Read lessLondon, England, United KingdomPermanent
We are seeking a Telecoms Security Compliance Analyst to support the assurance, governance and continuous improvement of security... Read more
We are seeking a Telecoms Security Compliance Analyst to support the assurance, governance and continuous improvement of security controls across telecommunications networks, systems and operational processes. The role will help ensure that technology services, suppliers and internal teams meet relevant regulatory obligations, industry standards and organisational security policies. You will work with technical, operational and risk stakeholders to assess compliance, identify weaknesses and promote practical improvements that protect the confidentiality, integrity and availability of telecoms services.
Key responsibilities will include planning and conducting security compliance reviews, control assessments and evidence-gathering activities across network, cloud, infrastructure and service environments. You will maintain compliance documentation, risk and action registers, control matrices and audit evidence, while tracking remediation activity through to completion. The role will also support internal and external audits, regulatory enquiries, security reviews and third-party assurance assessments. You will analyse findings, prepare clear reports for senior stakeholders and provide recommendations that are proportionate to business and operational risk. Additional duties may include reviewing security policies and procedures, monitoring changes in legislation and industry guidance, supporting risk assessments, and contributing to incident, business continuity and change-management processes.
Applicants should have experience in information security, technology risk, compliance, audit or telecommunications assurance, with a sound understanding of security frameworks and control principles. Familiarity with standards such as ISO 27001, NIST, CIS Controls, telecoms security guidance or relevant data protection and critical infrastructure regulations would be advantageous. You will need strong analytical and organisational skills, excellent written and verbal communication, and the ability to work confidently with both technical and non-technical audiences. Experience using governance, risk and compliance tools, interpreting technical evidence and managing multiple priorities is desirable. Relevant professional qualifications, such as CISA, CISSP, CRISC, ISO 27001 or equivalent experience, would be welcomed.
Read lessLondon, England, United KingdomPermanent
We are seeking an experienced Head of Compliance and Data Privacy for a 12-month fixed-term contract. This is... Read more
We are seeking an experienced Head of Compliance and Data Privacy for a 12-month fixed-term contract. This is a senior role with responsibility for leading the compliance and data privacy agenda across the organisation, ensuring that appropriate frameworks, policies and controls are in place and operating effectively. You will provide pragmatic, commercially focused advice to senior stakeholders and support a strong culture of ethical conduct, accountability and regulatory awareness.
Your responsibilities will include overseeing the compliance and data protection framework, monitoring changes in relevant laws and regulations, and assessing their impact on the business. You will maintain and update policies, procedures, risk assessments, registers and reporting processes, while coordinating assurance activity, internal reviews and remediation plans. The role will also involve advising on privacy matters including data protection impact assessments, data-sharing arrangements, data subject rights, records of processing and the management of potential incidents or breaches. You will act as a trusted point of contact for regulatory queries, audits and compliance-related investigations, ensuring that issues are escalated and resolved appropriately.
To succeed, you will have substantial experience in a senior compliance, risk, data protection or privacy leadership role, ideally within a regulated, complex or fast-paced environment. You should have strong knowledge of applicable data protection legislation and wider compliance principles, together with the ability to interpret regulatory requirements and translate them into practical business actions. Relevant professional qualifications, such as CIPP/E, CIPM, ICA or equivalent, are desirable. Excellent communication and stakeholder management skills are essential, as is the confidence to influence senior leaders and work collaboratively across departments. You will be organised, analytical and solutions-focused, with the ability to manage competing priorities and deliver effectively within a fixed-term appointment.
Read lessLondon, England, United KingdomContract
We are seeking an experienced Security Compliance Manager to lead the development, implementation and continuous improvement of information... Read more
We are seeking an experienced Security Compliance Manager to lead the development, implementation and continuous improvement of information security compliance programmes. The successful candidate will help ensure that security controls, policies and processes meet applicable legal, regulatory and industry requirements, while supporting business objectives and operational resilience. This role will work closely with technology, risk, legal, privacy, internal audit and business stakeholders to promote a consistent, risk-based approach to security and compliance.
Key responsibilities include maintaining the security compliance framework, policies, standards and control library; monitoring changes in relevant laws, regulations and industry frameworks; and assessing their impact on existing processes. You will coordinate internal and external audits, manage evidence collection, track remediation activities and report compliance status, risks and exceptions to senior stakeholders. The role will also involve conducting control assessments, supporting customer and supplier assurance activities, reviewing security questionnaires, and helping manage security incidents, risk acceptances and corrective action plans. You will contribute to awareness initiatives and provide practical guidance that enables teams to meet security requirements effectively.
Applicants should have substantial experience in information security, governance, risk or compliance, ideally within a regulated or complex operating environment. A strong understanding of frameworks and standards such as ISO 27001, SOC 2, NIST, CIS Controls or applicable data protection legislation is required. Experience managing audits, developing policies, interpreting regulatory requirements and presenting compliance information to senior audiences will be highly valued. Relevant professional qualifications, such as CISA, CISM, CRISC, CISSP or ISO 27001 Lead Auditor, are advantageous. You will need excellent analytical, organisational and communication skills, sound judgement, attention to detail and the ability to influence stakeholders at all levels. A proactive, collaborative approach and the confidence to challenge constructively are essential.
Read lessNorwich, England, United KingdomPermanent
We are seeking a Manager – Information Security (Compliance) to lead and develop information security compliance activities across... Read more
We are seeking a Manager – Information Security (Compliance) to lead and develop information security compliance activities across the organisation. This role will help ensure that policies, controls and processes align with applicable laws, regulations, contractual obligations and recognised security frameworks. You will work closely with technology, risk, legal, audit and business stakeholders to strengthen the organisation’s control environment and promote a culture of security and accountability.
Key responsibilities include managing the information security compliance programme; maintaining and improving security policies, standards and procedures; coordinating internal and external audits; and overseeing evidence collection, control testing, remediation plans and management reporting. You will monitor regulatory and industry developments, assess their impact, and translate requirements into practical controls and guidance. The role will also support risk assessments, third-party security reviews, security awareness initiatives, exception management and responses to customer or client security questionnaires. You will be expected to track compliance metrics, identify emerging risks and provide clear, actionable recommendations to senior stakeholders.
The successful candidate will have substantial experience in information security, IT risk, governance, audit or compliance, together with a strong understanding of frameworks such as ISO 27001, SOC 2, NIST or equivalent standards. Experience managing audits, control assurance programmes and remediation activity is essential, as is the ability to interpret complex regulatory requirements and communicate them effectively to technical and non-technical audiences. Relevant professional qualifications, such as CISM, CISSP, CISA, CRISC or ISO 27001 Lead Auditor, would be advantageous. Strong organisational, analytical and stakeholder-management skills are required, along with sound judgement, attention to detail and the confidence to challenge constructively.
Read lessKnutsford, England, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria